AWS
339 incident problems in AWS environments.
먼저 읽을 가이드
추천 문제
All problems (339)
NETWORK-1186Health checks fail from the load balancer subnet while user traffic still worksUsers can still reach the app, but the load balancer drains targets because health checks originate from a path the firewall policy never allowed.NetworkAdvanced22 minProK8S-1223IRSA works for most AWS calls but one SDK path still falls back to node credentialsA pod can access one AWS service through IRSA but another code path still appears to use the node role.KubernetesAdvanced22 minProK8S-1217Managed node joins successfully but service traffic still failsA scale event adds healthy nodes but a portion of traffic still fails immediately after.KubernetesAdvanced22 minProCICD-1212OIDC deploy works in the main workflow but fails after being moved into a reusable fileThe same shell commands now lose cloud auth because the reusable boundary no longer exposes the permission surface the original workflow relied on.CI/CDAdvanced22 minProK8S-1215Target group health is green but some client traffic still blackholesAn NLB-backed service passes health checks overall, but a portion of client traffic still disappears during scale changes.KubernetesAdvanced22 minProK8S-1212IRSA annotation is present but STS still denies AssumeRoleA pod with the correct service account still gets access denied after an auth migration.KubernetesAdvanced23 minProK8S-1206Node instances are healthy in AWS but never join the clusterA team changes node provisioning with a launch template and custom image and the EC2 instances never join the cluster.KubernetesAdvanced24 minProK8S-1201aws-auth still looks correct but kubelet bootstrap failsA cluster auth migration keeps the old mappings on paper, but node bootstrap starts failing because the node identity path has changed underneath.KubernetesAdvanced25 minProCICD-1197OIDC deploy works for the workflow caller but fails inside a reusable deployment workflowThe top-level job can authenticate to AWS, yet the reusable deployment workflow fails because the assumed identity boundary differs inside the called workflow.CI/CDAdvanced26 minProK8S-1196EKS auth migration breaks node accessA team follows EKS auth-mode migration guidance and deletes more aws-auth entries than intended. The cluster continues partly functioning but managed node groups stop behaving correctly.KubernetesAdvanced27 minProK8S-1181EKS CoreDNS stays PendingPublic EKS troubleshooting steps recommend restarting or scaling CoreDNS, but the real issue is that no eligible nodes exist for the pods.KubernetesAdvanced27 minProK8S-1186AWS Load Balancer Controller never reconcilesA team follows AWS re:Post guidance for the load balancer controller. The pod starts, but reconciliation never happens because the controller identity path is wrong.KubernetesAdvanced28 minProCICD-1181GitHub Actions OIDC trust works on main but fails on pull_requestThe same AWS deploy workflow succeeds on main and fails on pull_request because the OIDC token subject no longer matches the IAM trust policy.CI/CDAdvanced28 minProCICD-037CloudFormation change set succeeds but rollback fails on nested stack driftThe proposed change set looks safe, yet rollback breaks because one nested stack already drifted away from the expected template state.CI/CDAdvanced29 minProCICD-060Terraform PR plan is green but main apply uses a different variable setReviewers trust the plan output, but production apply behaves differently because the PR stage reads one workspace and tfvars path while the main branch apply uses another.CI/CDAdvanced29 minProK8S-1594A cert-manager DNS01 cleanup finishes and one order still waitsOne cert-manager order still waits after DNS01 hosted zone cleanup.KubernetesIntermediate8 minProK8S-1604A cert-manager order is valid and one challenge still waitsOne DNS challenge still waits after a hosted zone migration.KubernetesIntermediate8 minProK8S-1534A cert-manager DNS challenge starts and still failsDNS01 validation fails intermittently in zones managed by multiple reconcilers.KubernetesIntermediate10 minProK8S-1524A cert-manager DNS challenge starts fine and still failsDNS01 validation fails intermittently in zones managed by multiple reconcilers.KubernetesIntermediate10 minProK8S-1514A cert-manager order completes and renewal still failsACME DNS01 renewals fail intermittently in zones managed by both cert-manager and ExternalDNS.KubernetesIntermediate10 minPro